2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-35660 | MEDIUM | 5.4 | 0.9% | Apr 14, 2021 | Cross Site Scripting (XSS) in Monica before 2.19.1 via the journal page. |
| CVE-2020-28124 | MEDIUM | 5.4 | 0.5% | Apr 14, 2021 | Cross Site Scripting (XSS) in LavaLite 5.8.0 via the Address field. |
| CVE-2020-35419 | MEDIUM | 6.1 | 0.7% | Apr 14, 2021 | Cross Site Scripting (XSS) in Group Office CRM 6.4.196 via the SET_LANGUAGE parameter. |
| CVE-2020-35418 | MEDIUM | 5.4 | 0.5% | Apr 14, 2021 | Cross Site Scripting (XSS) in the contact page of Group Office CRM 6.4.196 by uploading a crafted svg file. |
| CVE-2020-29593 | MEDIUM | 5.4 | 0.6% | Apr 14, 2021 | An issue was discovered in Orchard before 1.10. The Media Settings Allowed File Types list field allows an attacker to a... |
| CVE-2020-21088 | MEDIUM | 4.8 | 0.8% | Apr 14, 2021 | Cross Site Scripting (XSS) in X2engine X2CRM v7.1 and older allows remote attackers to obtain sensitive information by i... |
| CVE-2020-21087 | MEDIUM | 6.1 | 1.4% | Apr 14, 2021 | Cross Site Scripting (XSS) in X2Engine X2CRM v6.9 and older allows remote attackers to execute arbitrary code by injecti... |
| CVE-2020-36322 | MEDIUM | 5.5 | 0.4% | Apr 14, 2021 | An issue was discovered in the FUSE filesystem implementation in the Linux kernel before 5.10.6, aka CID-5d069dbe8aaf. f... |
| CVE-2020-28590 | MEDIUM | 6.5 | 1.3% | Apr 13, 2021 | An out-of-bounds read vulnerability exists in the Obj File TriangleMesh::TriangleMesh() functionality of Slic3r libslic3... |
| CVE-2020-4964 | MEDIUM | 4.3 | 0.6% | Apr 12, 2021 | IBM Jazz Team Server products contain an undisclosed vulnerability that could allow an authenticated user to present a c... |
| CVE-2020-4920 | MEDIUM | 5.4 | 0.6% | Apr 12, 2021 | IBM Jazz Team Server products are vulnerable to stored cross-site scripting. This vulnerability allows users to embed ar... |
| CVE-2020-7924 | MEDIUM | 6.5 | 0.7% | Apr 12, 2021 | Usage of specific command line parameter in MongoDB Tools which was originally intended to just skip hostname checks, ma... |
| CVE-2020-15734 | MEDIUM | 5.5 | 0.2% | Apr 12, 2021 | An Origin Validation Error vulnerability in Bitdefender Safepay allows an attacker to manipulate the browser's file uplo... |
| CVE-2020-15942 | MEDIUM | 6.5 | 1.0% | Apr 12, 2021 | An information disclosure vulnerability in Web Vulnerability Scan profile of Fortinet's FortiWeb version 6.2.x below 6.2... |
| CVE-2020-23762 | MEDIUM | 5.4 | 0.8% | Apr 9, 2021 | Cross Site Scripting (XSS) vulnerability in the Larsens Calender plugin Version <= 1.2 for WordPress allows remote attac... |
| CVE-2020-23761 | MEDIUM | 6.1 | 1.0% | Apr 9, 2021 | Cross Site Scripting (XSS) vulnerability in subrion CMS Version <= 4.2.1 allows remote attackers to execute arbitrary we... |
| CVE-2020-36287 | MEDIUM | 5.3 | 9.0% | Apr 9, 2021 | The dashboard gadgets preference resource of the Atlassian gadgets plugin used in Jira Server and Jira Data Center befor... |
| CVE-2020-14106 | MEDIUM | 5.5 | 0.7% | Apr 8, 2021 | The application in the mobile phone can unauthorized access to the list of running processes in the mobile phone, Xiaomi... |
| CVE-2020-14103 | MEDIUM | 5.5 | 0.7% | Apr 8, 2021 | The application in the mobile phone can read the SNO information of the device, Xiaomi 10 MIUI < 2020.01.15. |
| CVE-2020-36316 | MEDIUM | 5.5 | 1.2% | Apr 7, 2021 | In RELIC before 2021-04-03, there is a buffer overflow in PKCS#1 v1.5 signature verification because garbage bytes can b... |
| CVE-2020-36315 | MEDIUM | 5.3 | 0.9% | Apr 7, 2021 | In RELIC before 2020-08-01, RSA PKCS#1 v1.5 signature forgery can occur because certain checks of the padding (and of th... |
| CVE-2020-24137 | MEDIUM | 5.3 | 1.4% | Apr 7, 2021 | Directory traversal vulnerability in Wcms 0.3.2 allows an attacker to read arbitrary files on the server that is running... |
| CVE-2020-24135 | MEDIUM | 6.1 | 0.9% | Apr 7, 2021 | A Reflected Cross Site Scripting (XSS) Vulnerability was discovered in Wcms 0.3.2, which allows remote attackers to inje... |
| CVE-2020-24138 | MEDIUM | 6.1 | 0.9% | Apr 7, 2021 | Cross Site Scripting (XSS) vulnerability in wcms 0.3.2 allows remote attackers to inject arbitrary web script and HTML v... |
| CVE-2020-11252 | MEDIUM | 5.5 | 0.2% | Apr 7, 2021 | Trustzone initialization code will disable xPU`s when memory dumps are enabled and lead to information disclosure in Sna... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now